
serverless-application-model
Transforms SAM templates into CloudFormation resources, generating Lambda functions, IAM roles, and policies with built-in serverless best practices.

Transforms SAM templates into CloudFormation resources, generating Lambda functions, IAM roles, and policies with built-in serverless best practices.

eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via…

Data pipelines for cloud config and security data. Build cloud asset inventory, CSPM, FinOps, and vulnerability management solutions. Extract from…

CloudMapper helps you analyze your Amazon Web Services (AWS) environments.

Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

Generates least-privilege AWS IAM policies based on resource ARNs and access levels, automating secure policy creation for cloud infrastructure.

PacBot (Policy as Code Bot)

Community-driven knowledge base for pentesting cloud environments and CI/CD pipelines: attack techniques, enumeration, privilege escalation, and…

Open-source cloud security platform that discovers attack paths, identifies misconfigurations, visualizes IAM access, and provides step-by-step…

Getting a handle on container security

Tooling for assessing an Azure AD tenant state and configuration

Create your own vulnerable by design AWS penetration testing playground

DevSec SSH Baseline - InSpec Profile

Like Envoy xDS, but for eBPF filters

Lan Tian's NixOS Configuration

DevSec Nginx Baseline - InSpec Profile

Powershell module for VMWare vSphere forensics

simply nodes and graphs